A lattice public key encryption method and device based on a super large scale MIMO
By employing a lattice public-key encryption scheme based on ultra-large-scale MIMO, utilizing the shortest lattice basis problem to generate public keys and combining MIMO precoding and singular value decomposition techniques, the problems of quantum attacks and increased antenna count for eavesdroppers in future 6G communications are solved, achieving highly secure and accurate communication decryption.
Patent Information
- Application Number
- CN202311048696.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-18
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2043-08-18
AI Technical Summary
Existing MIMO physical layer security technologies will struggle to effectively resist quantum attacks in the future 6G era, given the increased computing power and number of antennas used by eavesdroppers. Furthermore, they lack comprehensive security and correctness analysis, especially when the number of antennas used by eavesdroppers is infinite and far exceeds the number of legitimate antennas, resulting in insufficient security.
A lattice public-key encryption scheme based on ultra-large-scale MIMO is adopted. Public and private key pairs are generated by legitimate users, and the public key is generated using the shortest lattice basis problem. Combined with MIMO precoding and singular value decomposition techniques, the encryption and decryption of information are realized. The legitimate user terminal uses orthogonal basis and nearest plane algorithm for decoding.
It significantly improves communication security, resists quantum attacks, meets the security requirements of future 6G communication, is applicable to time-division duplex and frequency-division duplex channels, and remains effective even when the number of eavesdroppers' antennas is infinite and far exceeds the number of legitimate antennas.
Smart Images

Figure CN119497075B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of information security technology and encrypted communication technology of data, and particularly relates to a super large scale MIMO (Multiple Input Multiple Output) secure communication, a physical layer lattice public key encryption scheme and algorithm design. BACKGROUND
[0002] Considering the future Internet of Everything and the explosive growth of data, the research of the sixth generation mobile communication system has begun to rise. In the future, 6G may use millimeter wave frequency bands (26.5 GHz-300 GHz), and even higher terahertz frequency bands (0.1 THz-10 THz), which will bring a new network architecture system. Heterogeneity and full coverage are one of the visions of 6G networks, which requires various communication technologies to cooperate with each other to increase communication capacity and reduce cell interference. Among them, Multiple Input Multiple Output (MIMO) communication technology is to equip multiple antennas at the sending and receiving ends, which was first proposed by Marzetta researcher of Bell Laboratories (Marzetta T L. Noncooperative Cellular Wireless with Unlimited Numbers of Base Station Antennas[J]. IEEE Transactions on Wireless Communications, 2010, 9(11): 3590-3600). This technology can greatly enhance the antenna gain. The number of large-scale MIMO antennas can reach hundreds or even thousands, which can increase the spatial degrees of freedom of the communication system in a certain time and frequency resource. Chinese patent CN205104610U designs a MIMO antenna system and a mobile terminal. The patent shows that when the interval between the antennas is greater than half the wavelength, the channels between different MIMO antennas are independent of each other. The transmitting end can adjust the amplitude and phase of the transmitted signal by means of beamforming technology, so as to directional transmission to the receiving end, and finally improve the communication capacity and reduce the interference between different channels. In the future, super large-scale MIMO is expected to be deployed on the skyscrapers in the city, the crowded shopping malls, high-speed rail stations and the building walls of large concerts to improve the spatial multiplexing gain of the communication system, improve the spectrum efficiency and speed up the transmission rate. In the future 6G application, the security of MIMO data link transmission is particularly important. If the communication security in the 6G era only relies on the traditional upper encryption mechanism, it will be difficult to resist eavesdropping attacks as the computing power of the eavesdropper improves. Physical layer security uses the randomness of the channel to establish the advantage between the legal channel and the eavesdropping channel. Literature (Ren Pin-yi, Tang Xiao. Overview of Physical Layer Security Technology for 5G[J]. Journal of Beijing University of Posts and Telecommunications, 2018, 41(5): 69-77) shows that this technology can achieve perfect security in the sense of information theory.
[0003] Public key cryptosystem needs to be based on one-way trapdoor function to achieve computational security, and the traditional public key method is based on the discrete logarithm problem on finite field, large integer factorization problem and discrete logarithm problem on elliptic curve group, etc. In the communication system, if the eavesdropper can use quantum computer by quantum technology, the traditional RSA (Rivest Shamir Adleman), ECC (Ellipse Curve Cryptography), ElGamal and other public key cryptosystem can be attacked in polynomial time algorithm. In order to protect the information security in the future 6G era, it is particularly important to study the post-quantum public key cryptosystem. The current candidate post-quantum cryptosystem includes multivariate public key cryptosystem, coding-based cryptosystem, hash-based cryptosystem and lattice cryptosystem. Among them, lattice cryptosystem can reduce the worst case to the average case, has high security and fast encryption and decryption rate, which is particularly attractive. Lagrange and others began to study lattice problem in the 18th century, and the appearance of LLL lattice basis reduction algorithm (Lenstra AK, Lenstra H W, Lovász L. Factoring polynomials with rational coefficients [J]. Mathematische annalen, 1982, 261 (ARTICLE): 515-534) formally opened the era of lattice public key cryptography. LLL lattice basis reduction algorithm can be used to attack knapsack cryptosystem and RSA public key cryptosystem, and the general method is to convert it into a difficult problem on the lattice and output the corresponding solution in polynomial time. In addition, the one-way trapdoor function based on lattice can reduce the worst case of the difficult problem in the lattice to the average case, and realize the provable security of the lattice public key cryptosystem. When designing lattice public key cryptosystem, the difficult problems on the lattice that can be considered include the nearest vector problem, the shortest lattice basis problem, the small integer solution problem, the shortest vector problem and the fault-tolerant learning problem, etc. The public key cryptosystem based on lattice has a fast linear operation rate and cannot be attacked by the known quantum polynomial time algorithm.
[0004] MIMO physical layer security technology usually has three implementation ways: physical layer key generation, physical layer identity authentication and physical layer precoding secure transmission. The existing large-scale MIMO precoding technology is divided into four categories, including linear precoding, power allocation-based precoding, nonlinear precoding and machine learning-based precoding, which are studied in the literature (T. Kebede, Y. Wondie, J. Steinbrunn, H. B. Kassa and K. T. Kornegay, "Precoding and Beamforming Techniques in mmWave-Massive MIMO: Performance Assessment" in IEEE Access, vol. 10, pp. 16365-16387, 2022). Research shows that when the number of antennas of the eavesdropper is sufficient, the security of these precoding schemes will be greatly threatened. Shen et al. use path tracking algorithm to find the optimal precoding scheme (Sheng Z, Tuan H D, Duong T Q, et al. Beamforming Optimization for Physical Layer Security in MISO Wireless Networks [J]. IEEE Transactions on Signal Processing, 2018, 66(14) 3710-3723), which can maximize the security capacity, power and efficiency, but is only applicable to multiple-input single-output communication systems. In order to solve this problem, a batch optimization technique is applied to MIMO systems in the literature (Jiang M, Li Y, Zhang Q, et al. Robust Secure Beamforming in MIMO Wiretap Channels With Deterministically Bounded Channel Errors [J]. IEEE Transactions on Vehicular Technology, 2018, 67(10): 9775-9784), which theoretically derives the suboptimal precoding matrix. This method points out that even if the unknown eavesdropping channel matrix is unknown, the MIMO security capacity can be maximized.To further adapt to the requirements of MIMO security in the 6G era, Yang et al. combined the Taylor approximation with the second-order cone optimization algorithm to design MIMO precoding (Z. Yang, D. Li, N. Zhao, Z. Wu, Y. Li, and D. Niyato, "Secure Precoding Optimization for NOMA-Aided Integrated Sensing and Communication," in IEEE Transactions on Communications, vol. 70, no. 12, pp. 8370-8382, Dec. 2022), thereby maximizing the total secrecy rate of MIMO multi-users. Literature (Qi X, Chen Y, Jian R, et al. Two-level-enforced security with hybrid precoding for multicast massive MIMO wiretap systems [J]. Physical Communication, 2022, 54: 101817) proposes a hybrid precoding in a massive MIMO multicast scenario, which designs analog precoding based on the singular value decomposition (SVD) of the legitimate channel matrix and the semidefinite program (SDP). The complexity of this algorithm is proportional to the square of the number of antennas, and the use of this technology can optimize the MIMO physical layer security transmission rate. Subsequently, Marwan et al. pointed out that the zero forcing (ZF) algorithm can be used to reduce the interference between MIMO multi-users (Krunz M, Siyari P. Secure Linear Precoding in Overloaded MU-MIMO Wireless Networks [J]. IEEE Transactions on Communications, 2023). Subsequently, a variety of precoding techniques are used in the downlink to increase security, and this technology can also solve the problem of user overload, but this scheme requires the number of antennas at the transmitting end to be greater than the number of antennas at the eavesdropping end and the legitimate receiving end.The document (Jian J, Wang W Q, Chen H, et al. Physical-Layer Security for Multi-User Communications with Frequency Diverse Array-Based Directional Modulation [J]. IEEE Transactions on Vehicular Technology, 2023) simultaneously uses directional modulation and precoding technology based on frequency diversity array (FDA) in uplink and downlink, which can not only enhance the security of MIMO, but also eliminate interference arriving at different receiving antennas. Experiments show that this scheme is better than using zero forcing algorithm and singular value decomposition method alone. The document (Liu Nengsheng. Design and implementation of MIMO lattice cryptography [J]. Computer Engineering and Applications, 2018, 54(12): 10-13) found that if Gaussian random noise is introduced into the model, MIMO channels can exhibit random changes, making it equivalent to solving lattice hard problems for eavesdroppers to decode super-large-scale multiple-input multiple-output problems. Since the security of this scheme is based on the lattice hard problem, it can resist quantum attacks and selective ciphertext attacks. Although this scheme saves the key management process, it needs to share the key through the random channel matrix feature, and the premise assumption of this scheme needs to be based on the legal channel estimation process not being broken by the eavesdropper.
[0005] In summary, the current research on MIMO physical layer security needs to be based on the limited computing power of the eavesdropper, the limited number of eavesdropping antennas, or the eavesdropper's inability to obtain the legitimate channel state information. These assumptions may not be true in some cases and are not suitable for the security requirements of the future 6G era. There is relatively little research on large-scale MIMO physical layer precoding security design combined with lattice public keys, and there is a lack of perfect security and correctness analysis.
[0006] Thomas et al. (Dean T R, Goldsmith AJ. Physical-layer cryptography through massive MIMO [J]. IEEE Transactions on Information Theory, 2017, 63(8): 5419-5436) defined MIMO-Search and MIMO-Decision problems. At the same time, they proved that the eavesdropper decoding MIMO system signals is equivalent to solving lattice hard problems through the reduction process, which provides certain security analysis ideas for the present invention.
[0007] In addition, in practical applications, there are many scenarios that can use the idea of the present application. For example, in the 6G era, the base station may collapse due to natural disasters and the like, and the temporary emergency base station can be equipped with hundreds of antennas, and the secure communication between them can use the idea of the present application. On the other hand, if future communication uses terahertz electromagnetic waves (0.1THz-10THz), the signal wavelength will be further reduced, and the antenna spacing will be smaller. A super large antenna can be integrated on a very small area of a circuit board, and it is expected to be equipped with several hundred antennas in a mobile phone. At this time, the secure communication between the mobile phone and the base station can also use the idea of the present application. SUMMARY
[0008] To solve the above technical problems, the present application discloses a lattice public key encryption scheme based on super large MIMO, which can effectively protect the privacy information between the sending end and the receiving end and realize quantum attack resistance.
[0009] The technical scheme of the present application is as follows:
[0010] A lattice public key encryption method based on super large MIMO, the steps of which include:
[0011] 1) The legitimate user generates a public and private key pair and estimates the legitimate channel, and transmits the public key and channel state information in the form of plaintext to the base station;
[0012] 2) The base station encrypts the plaintext by means of MIMO precoding and public key, and transmits the obtained ciphertext to the legitimate user through the legitimate channel;
[0013] 3) The legitimate user decrypts according to the private key to obtain the original plaintext.
[0014] Further, the legitimate user generates a public and private key pair using the general difficult problem on the lattice. Specifically, the legitimate user generates a public and private key pair based on the shortest basis problem (SBP).
[0015] Further, the public and private key pair and other public parameters are generated by the following steps:
[0016] 1) The legitimate user end is equipped with M antennas, and the base station is equipped with N antennas. The values of M and N are disclosed, and the number of antennas at the legitimate user end is very large, which can be 512 in the present scheme, and both are public parameters.
[0017] 2) The legitimate user end generates an N-dimensional complex matrix R∈C N×N , all elements in the matrix are taken from a complex Gaussian random distribution with a mean of 0 and a variance of σ 2 , and the modulus of each element in the matrix R is required to be less than or equal to T (T is relatively small, for example, it can be taken as 4 in an embodiment of the present application).
[0018] 3) Calculation Then Σ' is generated as: Σ' = R + KI N ∈C N×N , where I N is an N-dimensional identity matrix.
[0019] 4) The legal user terminal randomly generates a unitary matrix P in the complex number field, and the modulus of the determinant of the matrix is 1. The generation method of P is: P = L t U t . Where L t is an N-dimensional lower triangular matrix, and U t is an N-dimensional upper triangular matrix. The modulus of the elements on the diagonal of the two matrices is 1, and the modulus of the elements at other non-zero positions can be 1 or 0.
[0020] 5) In the password scheme, the public key and the private key correspond to each other, which is called key pair. The public key is the part that is published externally, and the private key is the part that needs to be kept secret. Messages encrypted with the public key can only be decrypted using the private key. Therefore, according to the above key generation algorithm, Σ'P is the public key, and (Σ', P) is the private key.
[0021] Further, the legal user terminal obtains the channel state information according to the minimum mean square error (MMSE) channel estimation method, and the steps include:
[0022] 1) The base station sends a pilot signal s, which is transmitted to the receiving end, i.e. the legal user terminal, through the legal channel. The signal received by the legal user is Y. Y = Hs + e can be obtained, where H is the channel to be estimated, and e is the noise.
[0023] 2) The legal user terminal calculates When the minimum mean square error estimation is realized, the error vector is orthogonal to the calculation of here, that is, it satisfies the orthogonality principle. Then the statistical information E{HH H} of the channel matrix is calculated, where E represents the calculation of the mathematical expectation.
[0024] 3) The legal user terminal calculates the cross-correlation matrix of the matrix , where represents the noise intensity, represents the pilot signal intensity, represents the inverse of the signal-to-noise ratio.
[0025] 4) The legal user terminal calculates the cross-correlation matrix between the real channel matrix H and the matrix , that is, , where represents the matrix The complex conjugate transpose of .
[0026] 5) The final channel gain matrix obtained based on the MMSE channel estimation method This matrix is then transmitted to the base station in plaintext. Here, H represents the actual channel matrix. The channel matrix is obtained by the least squares method. This is the channel matrix obtained by the MMSE channel estimation method. The MMSE algorithm minimizes the mean square error of the estimated channel matrix, which is crucial in subsequent schemes.
[0027] Furthermore, the base station uses the channel gain matrix H and the public key to jointly design a novel precoding and physical layer encryption through the following steps:
[0028] 1) The base station uses the Singular Value Decomposition (SVD) method to decompose the channel matrix H, obtaining: H = U∑V H , where H∈C M×N ,U∈C M×M ,∑∈C M×N V∈C N×N U and V are both unitary matrices, representing the generalization of orthogonal matrices in the complex field;
[0029] 2) The base station originally transmits signal X. Using SVD precoding technology and the public key ∑′P, it precodes it into V∑′PX and transmits this result to the legitimate user through a legitimate channel.
[0030] Furthermore, the legitimate user terminal uses the Nearest Plane Algorithm and solves the equation, a process that can recover X in polynomial time. The steps include:
[0031] 1) The signal received by a legitimate user terminal is y=HV∑′PX+e1=U∑∑′PX+e1. Multiplying both sides of the equation by the conjugate transpose of the unitary matrix U, we can obtain U. H y = U H U∑∑′PX+U H e1=∑∑′PX+e3, where U H e1 and e3 are noise of equal magnitude;
[0032] 2) Valid users treat ∑∑′PX as lattice points in the complex field, U H Let y be any complex point in M-dimensional space, and then the process of eliminating e3 is equivalent to solving the Closest Vector Problem (CVP) on a lattice.
[0033] 3) The legal user terminal knows the private key ∑' and P, where the private key ∑' is a good orthogonal lattice basis, and the corresponding lattice point ∑∑'PX can be solved by using the Nearest Plane Algorithm, which is a polynomial time complexity algorithm;
[0034] 4) After ∑∑'PX is solved, ∑ is the result of SVD decomposition of the legal channel matrix and is public, ∑' and P are private keys and are also known by the legal user terminal, so the original sending signal X can be directly obtained by solving equations and normal decoding.
[0035] Further, the solution to the shortest vector problem on the lattice is based on an orthogonal lattice basis, and the Nearest Plane Algorithm is used to solve the shortest vector problem, and the steps include:
[0036] 1) Four matrices U H y∈C M×1 , ∑∈C M×N , ∑'∈C N×N , and P∈C N×N are input into the algorithm;
[0037] 2) ∑' is known as the orthogonal lattice basis, so the algorithm does not need to perform the LLL lattice basis reduction process;
[0038] 3) U H y is assigned to b: b←U H y;
[0039] 4) Each column of ∑' is regarded as an orthogonal lattice basis Each dimension is traversed to calculate where represents the inner product operation of the vector b and the vector , represents the nearest integer;
[0040] 5) From M dimensions to 1 dimension, b←b-c j b j is traversed and calculated;
[0041] 6) The algorithm finally outputs U H y-b, which is the value of ∑∑'PX.
[0042] A physical layer secure communication device includes an encoder, a modulator, a transmitting device connected in sequence at a sending end, a transmission channel, and a receiving device, a demodulator, and a decoder connected in sequence at a receiving end, and the encoder and the decoder and the transmitting device and the receiving device are arranged to perform the method of the application.
[0043] Compared with the prior art, the application has the following advantages:
[0044] 1) The super-large MIMO-based lattice public key encryption scheme proposed by the application significantly improves the security of communication, and the application is correct and feasible.
[0045] 2) When the number of antennas of the eavesdropper is infinite and much larger than the number of legal antennas, the application is also secure.
[0046] 3) When the distance between the eavesdropper and the legal end is less than one half of the wavelength, or the legal channel information is obtained by directly attacking the channel estimation process, the application is also secure.
[0047] 4) The application can be applied to time division duplex and frequency division duplex channels at the same time, and does not need to rely on channel reciprocity.
[0048] 5) The pre-coding public key encryption scheme proposed by the application is based on lattice cryptography, can resist current quantum attacks, and meets the requirements of future 6G for communication security.
[0049] 6) When future communication adopts terahertz frequency band (0.1THz-10THz), a large number of antennas can be integrated on a very small circuit board, and the application is also applicable to the communication between base stations and mobile phone users. If future 6G communication adopts terahertz electromagnetic waves, the signal wavelength will be further reduced, and the antenna spacing will be smaller, and a large number of antennas can be integrated on a very small circuit board. At this time, the security communication between the mobile phone and the base station, and the emergency security communication between the base stations can use the idea of the application. BRIEF DESCRIPTION OF DRAWINGS
[0050] Figure 1 is the super-large MIMO lattice public key encryption scheme architecture diagram in the method described in the embodiment of the application.
[0051] Figure 2 is the key generation MIMO.KeyGen algorithm diagram in the method described in the embodiment of the application.
[0052] Figure 3 is the flow chart of channel estimation and singular value decomposition of both parties in the method described in the embodiment of the application.
[0053] Figure 4 is the shortest lattice basis ∑' schematic diagram in the method described in the embodiment of the application.
[0054] Figure 5 is the receiver decryption MIMO.Dec algorithm diagram in the method described in the embodiment of the application.
[0055] Figure 6 is the relationship diagram of the decoding bit error rate and the signal-to-noise ratio of the legal receiving end and the eavesdropping end in the method described in the embodiment of the application. DETAILED DESCRIPTION
[0056] In order to make the purpose, technical scheme and advantages of the present application more clear, the present application is further described in detail below through examples.
[0057] The application discloses a lattice public key encryption scheme based on super large scale MIMO, which is composed of public key encryption and private key decryption. The public key encryption comprises the following steps: a legal user completes channel estimation by using a pilot transmitted by a base station end, and transmits the channel state information to the base station; the legal user end generates a public key based on the shortest lattice basis theory, and directly transmits the public key through a channel; and the base station end completes public key encryption of an original message and precoding operation based on channel matrix SVD decomposition based on the received public key and the channel state information. The private key decryption comprises the following steps: the legal user end generates a private key based on an orthogonal basis; and the noisy encrypted information is subjected to nearest plane algorithm operation based on the private key and the orthogonal basis, and finally decryption is realized. In the above steps, the key generation and decryption operation are completed at the legal user end.
[0058] Figure 1 The main framework of the present application is described, which is composed of public key encryption and private key decryption. The base station transmits a pilot S to a legal user, the legal user performs channel estimation by using the pilot, and performs SVD decomposition H=U∑V on the channel matrix H , wherein H∈C M×N , U∈C M×M , ∑∈C M×N , V∈C N×N , U and V are both unitary matrices, representing the generalization of the orthogonal matrix in the complex field. The legal user generates a public key ∑'P based on the shortest lattice basis problem, and transmits the public key and the channel state information to the base station. The base station encrypts an original message X according to the public key and a precoding matrix, and transmits V∑'PX to the other end, and the legal user decrypts by using a private key, thereby completing the whole process.
[0059] In general, the lattice public key encryption scheme based on super large scale MIMO proposed in the present application significantly improves the security of communication. When the number of antennas of an eavesdropper is infinite and much larger than the number of antennas of a legal user, the present application is also secure. When the distance between the eavesdropper and the legal user is less than one half of the wavelength, or the channel estimation process is directly attacked to obtain the legal channel information, the present application is also secure. The present application can be simultaneously applied to time division duplex and frequency division duplex channels and does not need to rely on channel reciprocity. The precoding encryption scheme proposed in the present application is based on lattice cryptography, can resist the quantum attack at present, and can adapt to the requirement of communication security in the future 6G. When the future communication adopts terahertz frequency, a large number of antennas can be integrated on a very small circuit board, and the present application is also applicable to the communication between a base station and a mobile phone user.
[0060] Figure 2A key generation algorithm MIMO.keyGen (see Table 1 for the description of the symbols in the algorithm) is described, which shows the generation process of the public key and the private key. The base station is equipped with M antennas, and the legitimate user is equipped with N antennas. The values of M and N are disclosed, both of which are large, and in the present scheme, 512 can be taken. Both are public parameters. Then, the legitimate user generates an N-dimensional complex matrix R∈C N×N All elements in the matrix are taken from a complex Gaussian random variable with a mean of 0 and a variance of σ 2 , and the modulus of each element of the matrix R is less than or equal to T (T is relatively small, and in the present application, 4 can be taken). Then, the following is calculated Then the legitimate user generates ∑' as follows: ∑' = R + KI N ∈C N×N , where I N is an N-dimensional identity matrix. Subsequently, the legitimate user randomly generates a unitary matrix P in the complex number field, and the modulus of the determinant of the matrix is 1. The generation of P is as follows: P = LU. Where L is an N-dimensional lower triangular matrix, and U is an N-dimensional upper triangular matrix. The modulus of the elements on the diagonal of the two matrices is 1, and the modulus of the elements at other non-zero positions can be 1 or 0. Thus, the public key pk = ∑'P, and the private key sk = (∑', P).
[0061] Table 1 Description of symbols in the scheme
[0062]
[0063] Figure 3 A flowchart showing the channel estimation and singular value decomposition is shown. The base station transmits a pilot signal s, which is transmitted to the receiving end through a legitimate channel. The signal received by the legitimate user is Y. Then, the legitimate user calculates It can be obtained that the matrix and the estimated channel error matrix are orthogonal matrices, and the statistical information E{HH H} of the channel matrix is calculated. Subsequently, the legitimate user end calculates the cross-correlation matrix of the matrix , where represents the noise intensity, represents the pilot signal intensity, represents the inverse of the signal-to-noise ratio. The legitimate user calculates the cross-correlation matrix between the real channel matrix H and the matrix using the same method. Finally, the channel gain matrix obtained by the MMSE (Minimum Mean Square Error) channel estimation method is obtained, and this matrix is transmitted to the base station in plaintext. Above, H is the real channel matrix, is the channel matrix obtained by the least squares method, The channel matrix obtained by the MMSE channel estimation method. After receiving the channel state information, the base station decomposes the channel matrix H by singular value decomposition (SVD) to obtain: H = U∑V H , where H∈C M×N , U∈C M×M , ∑∈C M×N , V∈C N×N , U and V are both unitary matrices, representing the generalization of the orthogonal matrix in the complex number field.
[0064] The legitimate user transmits ∑'P to the base station through the public channel, and the eavesdropper can also obtain ∑'P. If it is difficult for the eavesdropper to derive ∑' and P from ∑'P, ∑'P can be used as a public key and ∑' and P can be used as a private key. This part will explain from the perspective of lattice cryptography that it is difficult to derive ∑' and P from ∑'P. A lattice can be represented by different lattice bases, and there is a relationship between the orthogonality defect of the lattice base vector and the length of the lattice base vector. Assuming that [b1, b2, …, b n ] is a set of lattice bases of a lattice L, the orthogonal defect of [b1, b2, …, b n ] can be defined as where det(L) represents the determinant of the lattice L. According to the generation mode of ∑'∈C N×N , the modulus length of the elements on the diagonal of the matrix is much larger than that of the elements at other positions, so ∑'∈C N×N can be used as a lattice base with a small orthogonal defect. After transformation by the unimodular matrix P, ∑'P is a bad base, as shown in Figure 4 , and it is difficult to restore ∑' from the bad base ∑'P. This can be understood as finding the shortest base vector [b1, b2, …, b n ] of the lattice L that generates the shortest lattice base under the specified length definition, for example This process is to solve the shortest lattice base problem (SBP).
[0065] The original signal transmitted by the base station is X, which is now precoded and encrypted as V∑'PX. The signal received by the legitimate receiving end is y = U∑∑'PX + e1, and the ciphertext at this time is y∈C M×1 , the private key is ∑'∈C N×N and P∈C N×N , and the plaintext X∈C N×1 . The following three cases will cause the eavesdropper to obtain the channel state information H and V:
[0066] (1) The distance between the eavesdropper and the legitimate receiving end is less than one half of the signal wavelength;
[0067] (2) When the legal user transmits the channel state information to the base station, the process can be eavesdropped;
[0068] (3) The base station and the legal user select to actively disclose the channel state information.
[0069] The security of the scheme does not depend on the unknown channel state information, but only on the computational complexity theory, so U∈C M ×M ∑∈C M×N can be used as a public parameter. The legal end uses the private key ∑'∈C N×N and P∈C N×N , and the process of solving the signal X is a polynomial time complexity that can be solved.
[0070] At the same time, the signal received by the eavesdropping end is y e = GV∑'PX + e2, where G is the eavesdropping channel, which has good orthogonality, but GV∑'P will disturb this orthogonality and stretch it in different dimensions. At this time, the ciphertext is y e , the public key is ∑'P, the known parameters are V and G, and the expected plaintext to be solved is X. Even if the eavesdropper can obtain V and G, but cannot separate ∑' and P, it is equivalent to solving the CVP problem on a bad base, resulting in an exponential time complexity for the eavesdropper to solve X. By comparing the legal channel and the equivalent eavesdropping channel matrix, this process is equivalent to establishing a certain channel advantage.
[0071] Analysis and evaluation:
[0072] 1) Correctness analysis:
[0073] The signal received by the legal receiving end is y = U∑∑'PX + e1, and the conjugate transpose of the unitary matrix U is multiplied on both sides of the equation to obtain U H y = U H U∑∑'PX + U H e1 = ∑∑'PX + e3, where e3 and e1 are both noise. Because U is a unitary matrix ∈ C M×M , we have UU H = I M . e1 is noise ∈ C M×1 , and the norm of U H e1 can be calculated by this process: Therefore, the norm of U H e1 is equal to the norm of e1. The unitary matrix U H performs an orthogonal transformation on the vector e1, which does not change the length of the vector e1. This process reflects the norm-preserving property of the unitary matrix. Therefore, e3 and e1 are both noise and have the same size.
[0074] Let ∑∑'PX be a lattice in complex field, U H y be an arbitrary complex point in M-dimensional space, the process of eliminating noise e3 is essentially solving the Closest Vector Problem (CVP) problem in the lattice. The problem is defined as follows: given a lattice Λ and a point t in space, the goal is to find the closest lattice vector to t.
[0075] Since the lattice basis ∑' has good orthogonality, the closest plane algorithm can be used to directly solve the closest lattice point, as shown in the receiver decryption MIMO.Dec algorithm. Figure 5 The specific solving algorithm is as follows:
[0076] (1) The algorithm inputs four complex matrices U H y∈C M×1 , ∑∈C M×N , ∑'∈C N×N , P∈C N×N ;
[0077] (2) Since ∑' is the orthogonal basis of the lattice, the algorithm does not need to perform LLL lattice basis reduction process;
[0078] (3) Assign U H y to b: b←U H y;
[0079] (4) Take each column of ∑' as a lattice basis Iterate through each dimension to calculate where represents the inner product operation of vector b and vector , represents the nearest integer;
[0080] (5) From M-dimensional to 1-dimensional, iterate to calculate b←b-c j b j ;
[0081] (6) The algorithm finally outputs U H y-b, which is the value of ∑∑'PX.
[0082] The closest plane algorithm is also known as Babai algorithm. The final output of the algorithm is ∑∑'PX, and then the original sending signal X can be directly obtained through solving equations and normal decoding process. Therefore, the present application is correct, and the computational complexity is in the polynomial time level.
[0083] 2) Security analysis:
[0084] The signal received by the eavesdropping end is y e= GV∑'PX + e2. The eavesdropper can also perform SVD decomposition based on the estimation of the eavesdropping channel matrix G, that is, G = U e ∑ e V e H where G ∈ C E×N , U e ∈ C E×E , ∑ e ∈ C E×N , V e ∈ C N×N , U e and V e are unitary matrices, which represent the generalization of orthogonal matrices in the complex number field.
[0085] Similar to the legitimate user, the eavesdropper further processes the signal, and simultaneously multiplies the conjugate transpose of the unitary matrix U e on both sides of the equation, to obtain According to the invariance of the unitary matrix, we have and e4are two noises of equal size. PX hides the structure of X, even if the eavesdropping end adjusts the value of V e H but for the eavesdropping user, the process of solving X is equivalent to solving the Closest Vector Problem (CVP) on the bad basis ∑'P, which is difficult.
[0086] 3) Experimental performance evaluation:
[0087] The scheme proposed in the present application is implemented by using the MATLAB R2023a simulation platform, and the program running environment is Windows 11, 12 th Gen Intel(R)Core(TM)i5-12500 (12 CPUs), ~3.0 GHz and 8192 MB RAM. The experiment constructs a two-dimensional space model, in which the values of the elements in the channel matrix are affected by large-scale fading and small-scale fading, the number of antennas is set to 512, and the modulation mode adopts 16-QAM (Quadrature Amplitude Modulation, Quadrature Amplitude Modulation). Figure 6The simulation results of the scheme are shown in the figure, and the decoding error rates of the receiving end and the eavesdropping end change with the increase of the signal-to-noise ratio. The figure is divided into two parts, the upper part is the error rate of the private key decryption, and the lower part is the error rate of the private key decryption. In the upper part, the solid line represents that when the signal-to-noise ratio increases from-10dB to 10dB, the decoding error rate of the receiving end decreases from 0.15 to nearly 0. When the signal-to-noise ratio continues to increase from 10dB to 80dB, the error rate tends to 0. It is illustrated that when the receiving end decrypts by using the known private key, the decoding correctness is significantly improved by using the nearest plane algorithm, and the dashed line represents that when the eavesdropping end also masters the private key, similar results can be obtained as the receiving end (such as Figure 6 , the two curves are approximately coincident in most regions). In the lower part, the dashed line represents that when the signal-to-noise ratio increases from-10dB to 10dB, the decoding error rate of the eavesdropping end is close to 0.5, which is the worst decoding condition, and it is illustrated that in the scheme, the eavesdropping end cannot obtain the original plaintext information. When the signal-to-noise ratio continues to increase from 10dB to 80dB, the error rate has a certain downward trend, which illustrates that when the eavesdropping end directly decodes without knowing the private key, the error rate is high, and the decoding performance is much worse than that of the legal receiving end with the private key. The solid line illustrates that when the legal receiving end also does not know the private key, similar results can be obtained as the eavesdropper. The comparison between the upper and lower parts illustrates that (1) when the private key is possessed and combined with the nearest plane algorithm, the decoding error rate can be greatly reduced, and (2) the security of the scheme does not require a secret channel matrix, and the decoding correctness depends on the design of the pre-encoding of the scheme. In Figure 6 , the eavesdropping channel G and the legal channel H are different, and a total of four curves can control the influence of irrelevant variables. No matter which curve, when the signal-to-noise ratio increases to a certain degree, the error rate will appear a downward trend, which conforms to the basic logic of communication.
[0088] In summary, the performance of the scheme is excellent in security and feasibility, and a more secure communication system can be provided for the legal user.
[0089] 4) Scheme comparison and analysis:
[0090] Traditional MIMO precoding schemes generally focus on how to eliminate interference, and the security of MIMO precoding technology alone is weak. In order to realize secure transmission, it is usually necessary to assume that the number of antennas of the eavesdropper is limited, the distance between the eavesdropper and the legitimate end is far enough (usually greater than one half of the signal wavelength), the system is time division duplex and satisfies the channel reciprocity. These requirements and assumptions are unreasonable in the future 6G security scenario, and it is also difficult to resist quantum attacks. Literature (Liu, Nian-sheng. Design and implementation of MIMO lattice cryptosystem [J]. Computer Engineering and Applications, 2018, 54(12): 10-13) found that if the MIMO channel can exhibit random changes, then the eavesdropper is equivalent to solving the hard problem on the lattice for decoding super large scale multiple input multiple output (MIMO) problem. The security of this literature (to be replaced by literature [1] in Table 2) is based on the hard problem on the lattice, so it can resist quantum attacks and selective ciphertext attacks. Although this scheme saves the key management process, it needs to share the key through the random channel matrix feature, and the premise assumption of this scheme is that the legitimate channel estimation process is not attacked by the eavesdropper.
[0091] In the present application, a new precoding scheme based on the shortest lattice basis problem on the lattice is designed, that is, a public key encryption scheme based on the lattice at the physical layer. This scheme does not need to assume any unreasonable premise condition, and when the number of antennas of the eavesdropper is infinite and much larger than the number of antennas of the legitimate end, when the distance between the eavesdropper and the legitimate end is less than one half of the wavelength, or when the channel estimation process is directly attacked to obtain the legitimate channel information, the present application is also secure. The present application can be applied to time division duplex and frequency division duplex channels at the same time, and does not need to rely on channel reciprocity, and can meet the 6G security requirements even under quantum attacks.
[0092] The security comparison of the super large scale MIMO lattice public key encryption scheme proposed in the present application and the traditional MIMO precoding scheme and the literature [1] is shown in the following Table 2.
[0093] Table 2 Security comparison of precoding schemes
[0094]
[0095] Another embodiment of the present application provides a physical layer secure communication device, comprising an encoder, a modulator, a transmitting device connected in sequence at the sending end, a transmission channel, and a receiving device, a demodulator and a decoder connected in sequence at the receiving end, the encoder and the decoder and the transmitting device and the receiving device are arranged to perform the method of the above-mentioned present application.
[0096] Another embodiment of the present application provides a computer device (computer, server, smart phone, etc.) comprising a memory and a processor, the memory storing a computer program configured to be executed by the processor, the computer program comprising instructions for performing the steps of the method of the present application.
[0097] Another embodiment of the present application provides a computer readable storage medium (such as ROM / RAM, magnetic disk, optical disk) storing a computer program, the computer program being executed by a computer to implement the steps of the method of the present application.
[0098] The above embodiments are only used to illustrate the technical solutions of the present application but not to limit the present application, and any modifications or equivalent replacements to the technical solutions of the present application made by those skilled in the art without departing from the spirit and scope of the present application shall be covered by the protection scope of the present application, which is defined by the claims.
Claims
1. A lattice-based public-key encryption method based on massive MIMO, characterized by, The method comprises the following steps: A legal user generates a public-private key pair and estimates a legal channel, and transmits the public key and channel state information in plaintext to a base station; The base station encrypts the plaintext by means of MIMO precoding and the public key, and transmits the obtained ciphertext to the legal user through the legal channel; The legal user decrypts according to the private key to obtain the original plaintext; The legal user generates the public-private key pair by the following steps: The legal user end is equipped with M antennas, and the base station is equipped with N antennas, and the values of M and N are disclosed; A legitimate user terminal generates an N-dimensional complex matrix R e C N×N All elements in the matrix are taken from a complex Gaussian random distribution with mean 0 and variance σ 2 The modulus of each element in the matrix R is required to be less than or equal to T; Computing Σ' is then generated as: Σ' = R + KI N ∈ C N×N where I N is the N-dimensional identity matrix; The legal user terminal randomly generates a unitary matrix P in a complex field, and a determinant of the matrix has a length of 1, and the matrix P is generated in the following manner: P=L t U t , wherein L t is an N-dimensional lower triangular matrix, and U t is an N-dimensional upper triangular matrix; Wherein, Σ'P is the public key, and (Σ', P) is the private key.
2. The method of claim 1, wherein, The legal user obtains the channel state information according to the minimum mean square error (MMSE) channel estimation method by the following steps: The base station transmits a pilot signal s through the legal channel to the receiving end, i.e., the legal user end, and the signal received by the legal user end is Y, Y = Hs + e, wherein H is a real channel matrix to be estimated, and e is noise; Legal user end computing For the channel matrix obtained by the least square method, when the minimum mean square error estimation is implemented, the error vector is orthogonal to the signal vector, that is, the orthogonality principle is satisfied, and then the statistical information E{HH H} of the channel matrix is calculated, wherein E represents the calculation of the mathematical expectation. Legitimate user end computing matrix correlation matrix wherein represents the noise intensity, represents the pilot signal intensity, represents the inverse of the signal-to-noise ratio; The legitimate user calculates the cross-correlation matrix between the real channel matrix H and the matrix i.e. wherein denotes the complex conjugate transpose of the matrix ; The channel gain matrix according to the MMSE channel estimation method and this matrix is transmitted in clear form to the base station.
3. The method of claim 2, wherein, The base station jointly designs a new type of precoding and physical layer encryption by means of the matrix H and the public key by the following steps: The base station decomposes the matrix H by singular value decomposition method to obtain H=U∑V H , where H∈C M×N , U∈C M×M , ∑∈C M×N , and V∈C N×N . U and V are both unitary matrices, representing a generalization of orthogonal matrices in the complex number field. The base station originally transmits a signal X, and performs precoding by means of SVD precoding technology and the public key Σ'P to obtain VΣ'PX, and transmits the result to the legal user through the legal channel.
4. The method of claim 3, wherein, The legal user end recovers X in polynomial time by using the nearest plane algorithm and solving equations, and the steps include: The signal received by the legitimate user is y = HV∑'PX + e1= U∑∑'PX + e1. Multiply both sides by the conjugate transpose of U to get H y = U H U∑∑'PX + U H e1=∑∑'PX + e3, where U H e1and e3are equal in size. The legitimate user sees ΣΣ'PX as a lattice in the complex plane, U H y as an arbitrary complex point in M-dimensional space, and then the process of eliminating e3 is equivalent to solving the shortest vector problem on the lattice; The legal user end knows the private key Σ' and P, wherein the private key Σ' is a good orthogonal lattice basis, and the corresponding lattice point ΣΣ'PX is solved by using the nearest plane algorithm; After ΣΣ'PX is obtained, Σ is the result of SVD decomposition of the legal channel matrix S and is public, Σ' and P are private keys and are known by the legal user end, and the original transmission signal X is directly obtained by solving equations and normal decoding.
5. The method of claim 4, wherein, The shortest vector problem on the lattice is solved by using the nearest plane algorithm based on the orthogonal lattice basis, and the steps include: Input four matrices U H y e C M×1 ,∑ e C M×N ,∑' e C N×N , P e C N×N ; Since Σ' is an orthogonal lattice basis, there is no need to perform an LLL lattice basis reduction process; U H y is assigned to b: b←U H y; Consider each column of Σ' as an orthogonal lattice basis Compute across each dimension where denotes the vector b and the vector Take the inner product, denotes taking the nearest integer; From M to 1 dimension, traverse the calculation b <- b - c j b j ; Final output U H y - b, which is the value of ∑∑'PX.
6. A physical layer security communication apparatus, comprising: The method comprises the following steps:
7. A computer device, comprising: The computer readable storage medium stores a computer program, and the computer program is executed by a computer to implement the method of any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program is executed by a computer to implement the method of any one of claims 1-5.
Citation Information
Patent Citations
Multiple -input -multiple -output MIMO antenna system and mobile terminal
CN205104610U